logo

CVE-2026-31431: “Copy Fail,” the Nine-Year-Old Linux Bug Introduced in 2017

ID: 045628d0-a442-5bbd-8938-fd91cd675387

STIX ID: report--045628d0-a442-5bbd-8938-fd91cd675387

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-04-30

Date Updated: 2026-05-03

Author: Ameer Owda

...
...

**Copy Fail (CVE-2026-31431)** is a critical nine-year-old Linux kernel vulnerability that enables a reliable local privilege escalation and container escape by using AF_ALG and splice() to write into the page cache of readable files; a 732-byte Python script reproduces the exploit, affecting mainstream kernels shipped since 2017 and allowing attackers to gain root without leaving on-disk traces. Patch (mainline commit a664bf3d603d) and mitigations (disable algif_aead, seccomp filters, behavioral telemetry) are recommended immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.